Security thesis

Keep the castle. Distribute the gold.

Your customer data lives in a dozen systems that don’t talk to each other, and every team builds a taller wall around its own island. The safest-sounding answer — put it all in one big vault — is the one that will hurt you most.

The incumbent’s mistake

It isn’t having walls. It’s hoarding all the gold in one vault behind them.

That vault is the blast radius: one breach takes everything. And while it sits there, the hoarding also locks the value away from the people who need it. A single store of everything is simultaneously the biggest prize and the tightest bottleneck.

The fortress is the breach.

Keep the castle. Keep the moat.

None of this means tearing down the perimeter. Cloudflare’s walls still stand: the firewall, the DDoS shield, the edge governance. Keep every one of them.

What changes is what being inside them earns you. Nothing. Every request is re-verified, per action, whether it arrives from the open internet or from a service that has been running inside the walls for a year.

The castle governs access. It doesn’t store the treasure.

Distribute the gold

Instead of one vault, the value sits in many pockets — each in the system genuinely authoritative for it:

WhatWhere it lives
Card dataShopify — never touched, never mirrored
Identity and consentXano — your own instance, your key
Draft contentWebflow — a mirror, not a source
Grants and mandatesSigned, verifiable with a public key

Breach one and you get a fragment, never the hoard. There is no single secret to steal and no single point to take down.

And because the value is spread out for people and agents to use, distributing it is the accessibility. Security and reach in the same move — which is normally the trade you are asked to make.

Substrate is not security

People hear no-code and assume toy. But the tools are only where this runs — not what makes it safe. The controls are the primitives enterprise systems use: signed mandates, PKCE and OIDC, per-action authorization, offline-verifiable grants, real-time consent.

Judge the boundary logic, not the vendor logos.

The same core capability, operated by the person who needs it

The clearest way to say what this is: a Vault-grade key service that a designer or business analyst can operate. Not a lighter imitation of one — the same primitives, without the cluster.

Core security capabilityHashiCorp VaultCRM Sync
Envelope encryption (KEK wraps CEK)YesYes — AES-256-GCM, HKDF
EdDSA / Ed25519 signingYes — transitYes
Key rotation without re-encrypting dataYesYes — rekey and rewrap
Tamper-evident audit trailYesYes — hash-chained ledger
Short-lived credentialsYes — leasesYes — leases, 120s asset links
Policy-bound accessYes — policiesYes — capability grants

Parity on the primitives. The difference is who can run it — and what sits on top.

Vault assumes a platform team, a seal ceremony and a cluster to keep alive. This assumes one person with a browser.

PlusVaultCRM Sync
Verify a signature without calling the vaultNeeds the APIPublished JWKS
Mint an artifact — any file, keyed and ledgeredSecrets onlySTL, 3MF, firmware, docs
A purchase grants a capabilityNo commerce planeEntitlement rows
Consent checked at call timeNot its jobReal-time
Operated by a designer or BAPlatform teamNo cluster to run

Where Vault is still the right answer: dynamic database credentials, acting as a private PKI certificate authority, SSH certificate signing, and the breadth of its secret-engine ecosystem. If you need those, run Vault — the two are not mutually exclusive, and the walls are the same walls.

What Vault was never built for is the part that matters once agents start acting: an artifact a customer can be granted, a signature a third party can verify without asking you, and a permission that follows a person rather than a machine account. Vault predates that problem. It was designed when the actors were services you deployed, not agents transacting on someone’s behalf.

Why a closed boundary fails an AI actor

A closed, single-vendor system governs by containment. That is fine at human speed. An AI actor moves faster than a sealed system can respond, and containment cannot do the three things AI governance needs — while doing a fourth nobody wants.

Can’t heal

A corrupted record stays corrupted. A distributed shape rebuilds the mirror from its source.

Can’t fall back

One plane goes dark and governance goes with it. Across three legs, the guardrails stay on.

Can’t forward-deploy

An incident needs a new rule on every request in seconds, not in the next release window.

Taxes your success

Egress metering bills you to move your own data, charging you precisely as your AI starts working.

You hold the keys

The keys stay in your hand — owned, not rented from a platform. The proof of trust is a public key, so there is nothing secret for anyone to take, and nothing you have to ask us for in order to verify.

Keep the castle. Distribute the gold. Hold the keys. Nothing concentrated to steal, and everything reachable to the people — and the agents — you have allowed.

Watch it instead

The same argument as a three-minute film — the version to send to someone who will not read nine sections.

Keys to the Castle. Privacy-enhanced — no tracking cookie until you press play.

Set it up →  ·  Security posture in full →

CRM Sync — the entitlement layer for agentic commerce. Own your data. Govern every agent.